Vulnerabilities > Cisco > Firesight System Software > 4.10.3

DATE CVE VULNERABILITY TITLE RISK
2016-10-05 CVE-2016-6417 Cross-Site Request Forgery (CSRF) vulnerability in Cisco Firesight System Software
Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCva21636.
network
low complexity
cisco CWE-352
8.8
2016-10-05 CVE-2016-6420 Information Exposure vulnerability in Cisco Firesight System Software
Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request, aka Bug ID CSCur25467.
network
low complexity
cisco CWE-200
6.5